Security News

Roaming Mantis’ Android malware adds DNS changer to hack WiFi routers
2023-01-19 17:55

The Roaming Mantis malware distribution campaign has updated its Android malware to include a DNS changer that modifies DNS settings on vulnerable WiFi routers to spread the infection to other devices. O/XLoader Android malware that detects vulnerable WiFi routers based on their model and changes their DNS. The malware then creates an HTTP request to hijack a vulnerable WiFi router's DNS settings, causing connected devices to be rerouted to malicious web pages hosting phishing forms or dropping Android malware.

Datadog rotates RPM signing key exposed in CircleCI hack
2023-01-16 19:08

Cloud security firm Datadog says that one of its RPM GPG signing keys and its passphrase have been exposed during a recent CircleCI security breach. "As of January 16th, 2023, Datadog has no indication that the key was actually leaked or misused, but we are still taking the following actions out of an abundance of caution," Datadog said.

CircleCI's hack caused by malware stealing engineer's 2FA-backed session
2023-01-14 22:28

Hackers breached CircleCi in December after an engineer became infected with information-stealing malware that their 2FA-backed SSO session cookie, allowing access to the company's internal systems. In a new security incident report on the attack, CircleCi says they first learned of the unauthorized access to their systems after a customer reported that their GitHub OAuth token had been compromised.

Air France and KLM notify customers of account hacks
2023-01-06 20:21

Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their accounts were breached. KLM's official Twitter account confirmed the attack and told one of the impacted customers that "The attack was blocked in time and no miles were charged."

DraftKings warns data of 67K people was exposed in account hacks
2022-12-19 17:57

"In the event an account was accessed, among other things, the attacker could have viewed the account holder's name, address, phone number, email address, last four digits of payment card, profile photo, information about prior transactions, account balance, and last date of password change," the breach notification reads. After detecting the attack, DraftKings reset the affected accounts' passwords and said it implemented additional fraud alerts.

Apple security update fixes new iOS zero-day used to hack iPhones
2022-12-13 20:48

In security updates released today, Apple has fixed the tenth zero-day vulnerability since the start of the year, with this latest one actively used in attacks against iPhones. In October, Apple fixed a zero-day in the iOS Kernel.

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties
2022-12-12 19:58

Pwn2Own is now a multi-million "Hackers' brand" in its own right, having been bought up by anti-virus outfit Trend Micro and extended to cover many more types of bug than just browsers and desktop operating systems. Even in the Pwn2Own Toronto 2022 contest, where the cash amounts of the prizes far exceeded the value of the devices up to be hacked, winners got to take home the actual kit they broke into, thus retaining the original, literal sense of the competition.

Hack-for-Hire Group Targets Travel and Financial Entities with New Janicab Malware Variant
2022-12-10 11:46

Travel agencies have emerged as the target of a hack-for-hire group dubbed Evilnum as part of a broader campaign aimed at legal and financial investment institutions in the Middle East and Europe. The attacks targeting law firms throughout 2020 and 2021 involved a revamped variant of a malware called Janicab that leverages a number of public services like YouTube as dead drop resolvers, Kaspersky said in a technical report published this week.

How to hack an unpatched Exchange server with rogue PowerShell code
2022-11-22 19:54

Were] two zero-days that [could] be chained together, with the first bug used remotely to open enough of a hole to trigger the second bug, which potentially allows remote code execution on the Exchange server itself. It does mean that an automated Python script can't just scan the whole internet and potentially exploit every Exchange server in the world in a matter of minutes or hours, as we saw happen with ProxyLogon and ProxyShell in 2021.

Successful Hack of Time-Triggered Ethernet
2022-11-18 15:04

Time-triggered Ethernet is used in spacecraft, basically to use the same hardware to process traffic with different timing and criticality. On Tuesday, researchers published findings that, for the first time, break TTE's isolation guarantees.